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I claim: 

1. A method for establishing a connection from a user terminal to a network 
through a network access server, the method comprising the steps of: 
5 receiving a request from the user terminal to access the network with use of 

the network access server; and 

providing limited network access to the user terminal through the network 
access server, wherein providing said limited network access comprises providing 
network connectivity through said network access server between said user terminal 
10 and one or more predetermined enterprise-authenticated hosts and not providing 
network connectivity through said network access server between said user terminal 
and network sites other than said one or more predetermined enterprise-authenticated 
hosts. 

15 2. The method of claim 1 wherein the user terminal comprises a wireless 

device and the network access server comprises a wireless LAN hotspot server. 

3. The method of claim 2 wherein the wireless device and the wireless LAN 
hotspot server communicate with use of an IEEE 802.1 1 standard protocol. 

20 

4. The method of claim 1 wherein said request from the user terminal 
comprises an identification of a given enterprise, and wherein said one or more 
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enterprise-authenticated hosts consists of one or more VPN gateways associated with 
said given enterprise. 

5. The method of claim 4 wherein said user terminal has been pre-configured 
5 to automatically provide said identification of the given enterprise. 

6. The method of claim 4 wherein said request from the user terminal further 
comprises a fixed password, said fixed password uniquely associated with said given 
enterprise. 

10 

7. The method of claim 6 wherein said user terminal has been pre-configured 
to automatically provide said identification of the given enterprise and said fixed 
password. 

15 8. The method of claim 4 wherein said network access server is operated by a 

service provider, and wherein said service provider and said given enterprise have a 
pre-existing relationship. 

9. The method of claim 8 wherein said pre-existing relationship comprises an 
20 agreement that said limited network access provided to said user terminal incurs a 
charge billed by said service provider to said given enterprise. 
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10. The method of claim 1 wherein said network access server is operated by 
a service provider, wherein said service provider has a pre-existing relationship with 
each of one or more known enterprises, and wherein said one or more enterprise- 
authenticated hosts consists of one or more VPN gateways associated with each of 

5 said one or more known enterprises. 

11. The method of claim 10 wherein each of said pre-existing relationships 
comprises an agreement that said limited network access provided to said user 
terminal incurs a charge billed by said service provider to a corresponding one of said 

10 one or more known enterprises. 

12. The method of claim 1 wherein said step of providing said limited 
network access comprises the steps of: 

comparing a first IP address pair to a set of previously stored IP address pairs, 
15 the first IP address pair comprising an IP address of said user terminal and an IP 
address of an intended destination to which access has been requested by said user 
terminal, and each IP address pair in the set of previously stored IP address pairs 
comprising the IP address of a user terminal connected to said network access server 
and an IP address of one of said one or more enterprise-authenticated hosts; and 
20 providing network connectivity between said user terminal and said intended 

destination if and only if said first IP address pair matches one of said IP address pairs 
in said set of previously stored IP address pairs. 
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13. A network access server for establishing a connection from a user 
terminal to a network, the network access server comprising: 

means for receiving a request from the user terminal to access the network 
5 with use of the network access server; and 

means for providing limited network access to the user terminal through the 
network access server, wherein providing said limited network access comprises 
providing network connectivity through said network access server between said user 
terminal and one or more predetermined enterprise-authenticated hosts and not 
10 providing network connectivity through said network access server between said user 
terminal and network sites other than said one or more predetermined enterprise- 
authenticated hosts. 

14. The network access server of claim 13 wherein the user terminal 
15 comprises a wireless device and the network access server comprises a wireless LAN 

hotspot server. 

15. The network access server of claim 14 wherein the wireless device and 
the wireless LAN hotspot server communicate with use of an IEEE 802. 1 1 standard 

20 protocol. 
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16, The network access server of claim 13 wherein said request from the user 
terminal comprises an identification of a given enterprise, and wherein said one or 
more enterprise-authenticated hosts consists of one or more VPN gateways associated 
with said given enterprise. 

5 

17. The network access server of claim 16 wherein said user terminal has 
been pre-configured to automatically provide said identification of the given 
enterprise. 

10 18. The network access server of claim 16 wherein said request from the user 

terminal further comprises a fixed password, said fixed password uniquely associated 
with said given enterprise. 

19. The network access server of claim 18 wherein said user terminal has 
15 been pre-configured to automatically provide said identification of the given 

enterprise and said fixed password. 

20. The network access server of claim 16 wherein said network access server 
is operated by a service provider, and wherein said service provider and said given 

20 enterprise have a pre-existing relationship. 
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21. The network access server of claim 20 wherein said pre-existing 
relationship comprises an agreement that said limited network access provided to said 
user terminal incurs a charge billed by said service provider to said given enterprise. 

5 22. The network access server of claim 13 wherein said network access server 

is operated by a service provider, wherein said service provider has a pre-existing 
relationship with each of one or more known enterprises, and wherein said one or 
more enterprise-authenticated hosts consists of one or more VPN gateways associated 
with each of said one or more known enterprises. 

10 

23. The network access server of claim 22 wherein each of said pre-existing 
relationships comprises an agreement that said limited network access provided to 
said user terminal incurs a charge billed by said service provider to a corresponding 
one of said one or more known enterprises. 

15 

24. The network access server of claim 13 wherein said step of providing said 
limited network access comprises the steps of: 

comparing a first IP address pair to a set of previously stored IP address pairs, 
the first IP address pair comprising an IP address of said user terminal and an IP 
20 address of an intended destination to which access has been requested by said user 
terminal, and each IP address pair in the set of previously stored IP address pairs 
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comprising the IP address of a user terminal connected to said network access server 
and an IP address of one of said one or more enterprise-authenticated hosts; and 

providing network connectivity between said user terminal and said intended 
destination if and only if said first IP address pair matches one of said IP address pairs 
in said set of previously stored IP address pairs. 



